Organization: Meridian Trust Financial (illustrative) Owner: IAM / Identity Security Team Review cycle: Annually, or upon material process change
- HR record created in HRIS with role, department, manager, start date
- Identity provisioned in Identity Provider (automated via SCIM or manual fallback)
- Baseline access applied per role template
- Non-standard access requests submitted, justified, and approved (manager + system owner)
- SoD conflict check run against requested access
- Access confirmed active before or on start date
- Security awareness training assigned
- Provisioning actions logged with timestamp and approver
- Role change recorded in HRIS (new title, department, manager)
- Access recertification triggered automatically
- New-role baseline access provisioned
- Old-role access explicitly reviewed for removal (not just left in place)
- Old manager/system owner confirms removal or documents exception
- SoD conflict check run against combined old + new access
- Access delta (added/removed) logged with approver identity and timestamp
- Termination recorded in HRIS with effective date/time
- Termination type classified (standard vs. high-risk)
- Access disabled per SLA (same-day standard; before/at notification for high-risk)
- VPN, remote sessions, and badge/physical access revoked
- Manager confirms handover of shared mailboxes, files, and open tickets
- Contractor/vendor-specific access confirmed included (not HRIS-only scope)
- Access deleted/archived per data retention policy after retention window
- Full timeline logged: termination time, disablement time, gap measured against SLA
- Review campaign generated for the scheduled system(s)
- Entitlements presented with plain-language descriptions (not raw system codes)
- Manager attestation completed
- Independent system-owner review completed
- Unattested/flagged access removed
- Overdue reviews escalated per policy (e.g., 30-day escalation, 60-day auto-suspend)
- Completion rate and evidence retained for audit